This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
+3 more
Affected surfaces
ReleasePort's take
Moderate signalThe release adds a permission check to the users.CreateToken API and enforces consistent room permission checks during conversion/creation flows.
Why it matters: Security hotfixes address vulnerabilities; token generation now requires the user-generate-access-token permission, tightening access control for all API callers.
Summary
AI summarySecurity hotfixes address vulnerabilities and users.CreateToken now enforces the user-generate-access-token permission.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Adds permission check to users.CreateToken endpoint for token generation Adds permission check to users.CreateToken endpoint for token generation Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Security | Critical |
Enforces consistent room permission checks during channel-to-team conversion or team creation from existing room Enforces consistent room permission checks during channel-to-team conversion or team creation from existing room Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Dependency | Low |
Updates @rocket.chat/core-typings to 8.4.5, @rocket.chat/model-typings to 2.2.3, @rocket.chat/models to 2.2.3, @rocket.chat/rest-typings to 8.4.5 Updates @rocket.chat/core-typings to 8.4.5, @rocket.chat/model-typings to 2.2.3, @rocket.chat/models to 2.2.3, @rocket.chat/rest-typings to 8.4.5 Source: llm_adapter@2026-07-15 Confidence: high |
— |
Full changelog
Engine versions
- Node:
22.22.2 - Deno:
2.3.1 - MongoDB:
8.0 - Apps-Engine:
1.62.0
Patch Changes
-
Bump @rocket.chat/meteor version.
-
Bump @rocket.chat/meteor version.
-
(#41236 by @dionisio-bot) Security Hotfix (https://docs.rocket.chat/docs/security-fixes-and-updates)
-
(#41245 by @dionisio-bot) Security Hotfix (https://docs.rocket.chat/docs/security-fixes-and-updates)
-
(#41294 by @dionisio-bot) Ensures the
users.CreateTokenendpoint checks for theuser-generate-access-tokenpermission when generating a login token for another user -
(#41278 by @dionisio-bot) Ensures room permission checks are applied consistently regardless of how the room is identified when converting a channel to a team or creating a team from an existing room
-
Updated dependencies [bd5395461225863424e52ecc7ca6e1b0e6552135]:
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
- @rocket.chat/[email protected]
Security Fixes
- Security Hotfix (details in https://docs.rocket.chat/docs/security-fixes-and-updates)
- Security Hotfix (details in https://docs.rocket.chat/docs/security-fixes-and-updates)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]